Developers
Security
Review results, the key incident, trust assumptions.
- 14
- findings, review 1
- 29
- findings, review 2
- 2
- internal reviews
- 0
- external audits
- 1
- key incident, test funds
Security review, 30 September 2026
Scope: tesoro_core, both Game programs that existed then, sim_lst, tesoro_bridge and the EVM contracts. It found 14 findings (1 Critical, 3 High, 3 Medium, 6 Low, 1 Info). For each, a failing proof test was written first. The full table and fix commits are in docs/security/audit-2026-09-30.md in the repository.
| Finding | Severity | Issue | Status |
|---|---|---|---|
| F-01 | Critical | A Game's state could be delegated to a validator the attacker controls, committing a forged result. | Fixed and deployed: delegation pinned to the TEE validator via ProgramConfig and in the Game programs. |
| F-02 | High | A pre-funded permission address could skip privacy. | Fixed and deployed. |
| F-03 | High | A losing Hold'em Player could stall to the one-hour refund. | Fixed and deployed: the refund deadline is extended when the table is created. |
| F-04 | High | Out-of-order LayerZero delivery could strand Unlock or PayYield on an EVM vault. | Fixed: per-sequence idempotency; vaults redeployed. |
| F-05 | Medium | Sending simSOL straight to a vault repaid Debt. | Fixed and deployed: custody counts its own shares. |
| F-06, F-07, F-09, F-12 | Medium and Low | Last-second join forfeit; plain redeem burning an EVM-sourced Gema; joining before a Session exists; a Request stuck as Accepted. | Fixed and deployed (F-09 except match_id squatting). |
| F-13 | Low | A PayYield above accrued yield reverts while Solana has counted it. | Mitigated: LayerZero retries once yield catches up. |
| F-08, F-10, F-11, F-14 | Low and Info | Unbacked faucets and reserve; first-caller Config init; faucet griefing; rounding dust and notes. | Accepted for testnets. |
Implementation review, 30 September to 1 October 2026
Scope: the app, keeper, server routes, contracts and programs. It found 29 findings (P1: 2, P2: 14, P3: 13). The two P1s were an EVM vault underpaying yield after an earlier payout (SP-01, fixed with redeployed vaults) and a faucet quota rollback that could be bypassed (ST-01, fixed). Other fixes include Principal above u64 locking a deposit for good (PR-01), ETH redemption tracked against the wrong Source (SP-02, SP-03), a stale price re-stamped as fresh (OC-01), the web server holding admin keys (OC-02, now low-balance relayer keys), and one hung RPC stalling every keeper job (OC-05). The status table is in the repository's README.
Items that need a program upgrade were open at the last status update: a no-show turning a forfeit win into a refund (PR-02), an Advance priced from a feed up to 24 hours old (PR-03), and on-chain bounds on set_price.
Key compromise, 1 October 2026
At 05:26 UTC the original devnet deployer key AXwYStYVryJuZjNJjHHLPp6eVRc2TuESnW1pCMiUYrwV sent its whole balance, 24.63 devnet SOL, to another address (transaction 2WbwBf9X…FgYqiMWR). The key held only testnet funds, but it was the upgrade authority of every program, the admin of tesoro_core, sim_lst and tesoro_bridge, the LayerZero OApp delegate, and the owner of the fee recipient. The team treated it as compromised.
Response, the same day
- Upgrade authority of all programs moved to
7zr1j185zT8r6jcysC4LyrdSEJ13Up3xq4TFu6KQqh7M(verified on chain on 10 October 2026). - A
set_admininstruction, gated on the upgrade authority, was added to tesoro_core, sim_lst and tesoro_bridge, and used to rotate the Config, Pool and Store admins and the LayerZero delegate. - The Platform and Studio Fee recipient moved to a new Account. Fees the old Account had already collected stay under the old key.
- The web routes now sign with separate low-balance relayer keys, and a pre-commit secret scanner was added to the repository.
Signatures are in docs/deployments.md, under “Key compromise response”.
Residual risk and trust assumptions
- The oracle key and price feed are trusted. A wrong price mints the wrong number of Gemas.
- Privacy depends on MagicBlock's TEE attestation and operator. Cross-chain messages depend on the LayerZero DVN set (default: LayerZero Labs).
- One admin key holds every admin power and can upgrade every program. There is no multisig and no timelock.
- Faucets mint unbacked test tokens and withdrawals draw on an admin-funded reserve; admins can change rate parameters.
Not reviewed: the MagicBlock, LayerZero and Pyth programs themselves. The player-facing summary is on Risks and limits.
Reporting a problem
No dedicated security contact is published yet.